A Distributed MAPE-K Framework for Self-Protective IoT Devices

Michael Riegler, J. Sametinger, Michael Vierhauser
{"title":"A Distributed MAPE-K Framework for Self-Protective IoT Devices","authors":"Michael Riegler, J. Sametinger, Michael Vierhauser","doi":"10.1109/SEAMS59076.2023.00034","DOIUrl":null,"url":null,"abstract":"Internet of Things (IoT) devices have become ubiquitous in our everyday life, with security becoming an ever-growing issue as more and more cyber-attack incidents being reported, primarily due to deficiencies in existing security mechanisms. However, while, for example, cloud-based applications, or industrial automation systems of systems possess significant resources for monitoring health, and determining their status and correct behavior at runtime, IoT devices operate with limited hardware capabilities and under tight resource constraints, making monitoring, analysis, and response activities a challenging endeavor. Following the NIST Cybersecurity Framework, IoT devices need to identify, protect, detect, respond, and recover from cyber-attacks, unauthorized access, and other security threats. A common way to provide self-adaptation to changing conditions is the MAPE-K loop with four pivotal phases: Monitor, Analyze, Plan, and Execute. This paper presents DSec4IoT, a “Distributed MAPE-K Framework for Self-Protective IoT Devices”. Our framework leverages the idea of distributed MAPE-K patterns and establishes a model for managing and controlling Self-Protective IoT Devices. We evaluate our approach by simulating port scans and performing adaptation activities. Results have confirmed that DSec4IoT can be easily applied to detect and mitigate them.","PeriodicalId":262204,"journal":{"name":"2023 IEEE/ACM 18th Symposium on Software Engineering for Adaptive and Self-Managing Systems (SEAMS)","volume":"14 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-05-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 IEEE/ACM 18th Symposium on Software Engineering for Adaptive and Self-Managing Systems (SEAMS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SEAMS59076.2023.00034","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Internet of Things (IoT) devices have become ubiquitous in our everyday life, with security becoming an ever-growing issue as more and more cyber-attack incidents being reported, primarily due to deficiencies in existing security mechanisms. However, while, for example, cloud-based applications, or industrial automation systems of systems possess significant resources for monitoring health, and determining their status and correct behavior at runtime, IoT devices operate with limited hardware capabilities and under tight resource constraints, making monitoring, analysis, and response activities a challenging endeavor. Following the NIST Cybersecurity Framework, IoT devices need to identify, protect, detect, respond, and recover from cyber-attacks, unauthorized access, and other security threats. A common way to provide self-adaptation to changing conditions is the MAPE-K loop with four pivotal phases: Monitor, Analyze, Plan, and Execute. This paper presents DSec4IoT, a “Distributed MAPE-K Framework for Self-Protective IoT Devices”. Our framework leverages the idea of distributed MAPE-K patterns and establishes a model for managing and controlling Self-Protective IoT Devices. We evaluate our approach by simulating port scans and performing adaptation activities. Results have confirmed that DSec4IoT can be easily applied to detect and mitigate them.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
面向物联网设备自我保护的分布式MAPE-K框架
物联网(IoT)设备在我们的日常生活中无处不在,随着越来越多的网络攻击事件被报道,安全问题日益突出,主要原因是现有安全机制的不足。然而,尽管基于云的应用程序或工业自动化系统拥有大量资源来监控健康状况,并在运行时确定其状态和正确行为,但物联网设备在有限的硬件功能和严格的资源约束下运行,使得监控、分析和响应活动成为一项具有挑战性的工作。根据NIST网络安全框架,物联网设备需要识别、保护、检测、响应并从网络攻击、未经授权的访问和其他安全威胁中恢复。为不断变化的条件提供自适应的一种常用方法是MAPE-K循环,它具有四个关键阶段:Monitor、Analyze、Plan和Execute。本文介绍了DSec4IoT,一种“用于自我保护物联网设备的分布式MAPE-K框架”。我们的框架利用分布式MAPE-K模式的思想,并建立了一个管理和控制自我保护物联网设备的模型。我们通过模拟端口扫描和执行适应活动来评估我们的方法。结果证实,DSec4IoT可以很容易地应用于检测和缓解它们。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Dynamic Runtime Integration of New Models in Digital Twins Adaptive Controllers and Digital Twin for Self-Adaptive Robotic Manipulators Software Self-adaptation and Industry: Blame MAPE-K Artifact: Implementation of an Adaptive Flow Management Framework for IoT Spaces PlanIoT: A Framework for Adaptive Data Flow Management in IoT-enhanced Spaces
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1